A GP practice, group dental practice or medical centre usually has no IT person on staff. What it does have: a patient record system the whole team runs on, an agenda that can’t afford a single day of downtime, medical equipment hanging off the network, and a pile of data for which the law rightly applies its strictest category. Health data is special category personal data under the GDPR, and a breach isn’t just a fine risk. It’s a breach of trust with people who handed you their most private information.

Why healthcare tops the target lists

Attackers don’t pick targets by size but by pressure. A practice locked out of its records can’t prescribe safely, can’t refer, can barely consult. Every day of standstill touches patient care directly. That pressure has made healthcare a favourite ransomware target worldwide, and the attacks stopped limiting themselves to large hospitals long ago. To a criminal, a group practice without a security policy is more attractive than a hospital with one.

On top of that, the formal pressure is growing. Hospitals fall under NIS2, and what large healthcare institutions are obliged to do trickles down to everyone who works with them or refers to them. Questions about your information security no longer come only from the data protection authority.

The minimum baseline for a practice

The good news: what a practice minimally needs is manageable. It’s essentially the CyFun Basic logic applied to a medical environment.

Know what’s running. The record system, the agenda server, the router, the network printer that referral letters roll out of, the radiology supplier’s device that’s “temporarily” on the network. A current inventory is the starting point of everything.

Watch the critical parts. Is the record system up, are the backups succeeding, is there disk space left, is a certificate about to expire? Outages in a practice are typically discovered at eight in the morning, when the first patient is already in the waiting room. Detection at night means recovery before the first consultation.

Record what happens. Anyone obliged to report a data breach must be able to reconstruct what happened when. Without a log, every notification to the authority is guesswork, and guesswork looks remarkably bad in that kind of file.

The backup paradox

Almost every practice “has backups”. The question nobody can answer: did last night’s backup actually run, and has anyone ever tested whether it can be restored? A backup that has been quietly failing for weeks is one of the most common discoveries during an incident, at which point it is by definition discovered too late. Watching backup jobs is unspectacular work that, in a ransomware incident, makes the difference between a rough week and an existential crisis.

Outsourcing without losing control

A practice should be busy with patients, not dashboards. Which makes this a prime domain to have managed: the monitoring runs in the background, alerts go to whoever needs them, and you receive a monthly report you can drop straight into a GDPR file or supplier questionnaire. Through Althona I set up that environment with CheckMK and keep running it.

Want to know where your practice stands today? Book a no-obligation call. A first review of what’s running and what’s unwatched usually tells you enough.